CVE-2024-32119: Fortinet FortiClient EMS

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.

Affected products

  • Fortinet FortiClient EMS: from 6.2.0, up to and including 6.2.9; from 6.4.0, up to and including 6.4.9; from 7.0.0, up to and including 7.0.13; from 7.2.0, before 7.2.5 (fixed in 7.2.5); version 7.4.0 only

Published 2025-06-10. Last modified 2026-06-17.